Privacy Policy
Last updated: 7/24/2026
Who we are
This service is operated by FounderSync ("FounderSync", "we", "us"). FounderSync is the data controller responsible for personal data processed through foundersync.co.in. You can reach us at hello@foundersync.co.in.
What we collect
- Account data: your email address and authentication identifiers (e.g. Google sign-in ID).
- Audit content: the answers you and your co-founder submit, and the reports generated from them.
- Payment data: processed by Paddle, our Merchant of Record. We receive transaction metadata (order ID, amount, country) but never see your full card details.
- Technical data: IP address, device/browser info, and basic usage logs for security and reliability.
Why we process it and legal basis
- To provide the service (create account, run audit, generate report) — performance of a contract.
- To process payments and issue invoices via Paddle — performance of a contract and legal obligation.
- To secure the service (fraud/abuse prevention, logs) — legitimate interests.
- To send transactional email (report-ready notifications) — performance of a contract.
- To send occasional product updates, only where you have opted in — consent.
Who sees your answers
You see your own answers. Your co-founder sees theirs. We use both sets to generate your compatibility report. Your raw answers are never shown to your co-founder.
AI processing
Your answers are sent to a large language model (via Lovable AI Gateway) solely to generate your report. We do not use your answers to train any AI model.
Who we share data with
- Paddle — Merchant of Record for payments, subscription management, tax compliance, and invoicing.
- Supabase — database, authentication, and file storage hosting.
- Lovable AI Gateway — routes report-generation prompts to the underlying LLM provider.
- Resend — sends transactional email (e.g. report-ready notifications).
- Google — if you sign in with Google.
- Authorities — where required by law.
Security
We apply appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS) and at rest, row-level security in our database so users can only access their own records, scoped access tokens, least-privilege service credentials, and audit logging on privileged operations. No system is perfectly secure, but we treat your audit answers as sensitive by default.
Retention
Your responses and reports are stored for as long as you keep your account. You can request deletion at any time by emailing hello@foundersync.co.in; we will delete or anonymise your data unless we are required to retain it (e.g. tax records held by Paddle).
Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or export of your personal data, and object to or restrict certain processing. Email hello@foundersync.co.in and we will respond within one month. If you are in the UK/EEA you also have the right to lodge a complaint with your local supervisory authority.
Cookies
We use essential cookies for authentication and session management. We do not use advertising cookies.
Contact
Questions? Email hello@foundersync.co.in.
FounderSync